ZeroHour

Vulnerabilities

44 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-59174
Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability where an attacker sending a large volume of specially crafted messages may

Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability where an attacker sending a large volume of specially crafted messages may cause service degradation.

NVD description · AI analysis pending
7.1<1%
  • ericsson packet core controller
CVE-2026-25659
+2 in the same advisory: …25658 …25657
Ericsson Packet Core Gateway (PCG) versions prior to 1.30 contain an Improper Handling of Missing Values (CWE-230) vulnerability where an attacker continuously

Ericsson Packet Core Gateway (PCG) versions prior to 1.30 contain an Improper Handling of Missing Values (CWE-230) vulnerability where an attacker continuously sending a specially crafted message can cause service degradation. The impact continues as long the attack persists but the system recovers from the crashes when the attack stops.

NVD description · AI analysis pending
7.1<1%
  • ericsson packet core gateway
CVE-2026-25660
CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy.

CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Authentication bypass occurs when the URL ends with Authentication with certain function calls. This bypass allows assigning arbitrary permission to any user existing in CodeChecker. This issue affects CodeChecker: through 6.27.3.

NVD description · AI analysis pending
9.3<1%
  • ericsson codechecker
CVE-2024-53828
Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a vulnerability where an attacker sending a large volume of specially crafted messages may

Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a vulnerability where an attacker sending a large volume of specially crafted messages may cause service degradation.

NVD description · AI analysis pending
5.3<1%
  • ericsson packet core controller
CVE-2025-40842
+2 in the same advisory: …27260 …40841
Ericsson Indoor Connect 8855 versions prior to 2025.Q3 contains a Cross-Site Scripting (XSS) vulnerability which, if exploited, can lead to unauthorized disclos

Ericsson Indoor Connect 8855 versions prior to 2025.Q3 contains a Cross-Site Scripting (XSS) vulnerability which, if exploited, can lead to unauthorized disclosure and modification of certain information.

NVD description · AI analysis pending
8.5
group max
<1%
  • ericsson indoor connect 8855 firmware
CVE-2025-40843
CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy.

CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. CodeChecker versions up to 6.26.1 contain a buffer overflow vulnerability in the internal ldlogger library, which is executed by the CodeChecker log command. This issue affects CodeChecker: through 6.26.1.

NVD description · AI analysis pending
7.8<1% PoC
  • ericsson codechecker
CVE-2025-27258
+1 in the same advisory: …27259
Ericsson Network Manager (ENM) versions prior to ENM 25.1 GA contain a vulnerability, if exploited, can result in an escalation of privilege.

Ericsson Network Manager (ENM) versions prior to ENM 25.1 GA contain a vulnerability, if exploited, can result in an escalation of privilege.

NVD description · AI analysis pending
6.9
group max
<1%
  • ericsson network manager
CVE-2025-40836
+4 in the same advisory: …27261 …40837 …27262 …40838
Ericsson Indoor Connect 8855 contains an improper input validation vulnerability which if exploited can allow an attacker to execute commands with escalated pri

Ericsson Indoor Connect 8855 contains an improper input validation vulnerability which if exploited can allow an attacker to execute commands with escalated privileges.

NVD description · AI analysis pending
8.7
group max
<1%
  • ericsson indoor connect 8855 firmware
CVE-2025-1300
CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy.

CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. The CodeChecker web server contains an open redirect vulnerability due to missing protections against multiple slashes after the product name in the URL. This results in bypassing the protections against CVE-2021-28861, leading to the same open redirect pathway. This issue affects CodeChecker: through 6.24.5.

NVD description · AI analysis pending
6.1<1%
  • ericsson codechecker
CVE-2024-53829
CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy.

CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Cross-site request forgery allows an unauthenticated attacker to hijack the authentication of a logged in user, and use the web API with the same permissions, including but not limited to adding, removing or editing products. The attacker needs to know the ID of the available products to modify or delete them. The attacker cannot directly exfiltrate data (view) from CodeChecker, due to being limited to form-based CSRF. This issue affects CodeChecker: through 6.24.4.

NVD description · AI analysis pending
8.2<1% PoC
  • ericsson codechecker
CVE-2024-10081
+1 in the same advisory: …10082
Authentication Bypass in Ericsson CodeChecker Grants Superuser API Access

Ericsson CodeChecker, an analyzer tooling and defect database/viewer for Clang Static Analyzer and Clang Tidy, contains a critical authentication bypass (CWE-288/CWE-420) in all versions through 6.24.1. The flaw is triggered when an API request URL ends with 'Authentication', causing the server to skip authentication checks. An unauthenticated remote attacker can then obtain superuser access to all API endpoints except /Authentication itself, allowing them to add, edit, and remove products and otherwise administer the defect database. Any CodeChecker deployment running an affected version is exposed, with the greatest risk for instances reachable from the internet or shared networks. No public proof-of-concept is known and the flaw is not in CISA's KEV, but EPSS assigns a 39.1% probability of exploitation within 30 days (99th percentile), indicating elevated near-term risk.

Do: Upgrade to a CodeChecker release newer than 6.24.1, as the advisory lists every version through 6.24.1 as affected. Until patched, restrict network access to the CodeChecker web/API endpoint (VPN, firewall rules, or an authenticating reverse proxy) to limit unauthenticated access. Review server logs for API requests whose URL ends with 'Authentication', which would indicate attempted or successful exploitation.

10.0
group max
39%
  • Ericsson CodeChecker through 6.24.1 (all versions up to and including 6.24.1)
nichelikely low thousands of deployments at most; unknown precisely
CVE-2023-49793
CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy.

CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Zip files uploaded to the server endpoint of `CodeChecker store` are not properly sanitized. An attacker, using a path traversal attack, can load and display files on the machine of `CodeChecker server`. The vulnerable endpoint is `/Default/v6.53/CodeCheckerService@massStoreRun`. The path traversal vulnerability allows reading data on the machine of the `CodeChecker server`, with the same permission level as the `CodeChecker server`. The attack requires a user account on the `CodeChecker server`, with permission to store to a server, and view the stored report. This vulnerability has been patched in version 6.23.

NVD description · AI analysis pending
6.5<1% PoC
  • ericsson codechecker
CVE-2024-25007
Ericsson Network Manager (ENM), versions prior to 23.1, contains a vulnerability in the export function of application log where Improper Neutralization of Form

Ericsson Network Manager (ENM), versions prior to 23.1, contains a vulnerability in the export function of application log where Improper Neutralization of Formula Elements in a CSV File can lead to code execution or information disclosure. There is limited impact to integrity and availability. The attacker on the adjacent network with administration access can exploit the vulnerability.

NVD description · AI analysis pending
7.1<1%
  • ericsson network manager
CVE-2023-39909
Ericsson Network Manager before 23.2 mishandles Access Control and thus unauthenticated low-privilege users can access the NCM application.

Ericsson Network Manager before 23.2 mishandles Access Control and thus unauthenticated low-privilege users can access the NCM application.

NVD description · AI analysis pending
8.8<1%
  • ericsson network manager
CVE-2022-47531
An issue was discovered in Ericsson Evolved Packet Gateway (EPG) versions 3.x before 3.25 and 2.x before 2.16, allows authenticated users to bypass system CLI a

An issue was discovered in Ericsson Evolved Packet Gateway (EPG) versions 3.x before 3.25 and 2.x before 2.16, allows authenticated users to bypass system CLI and execute commands they are authorized to execute directly in the UNIX shell.

NVD description · AI analysis pending
8.8<1%
  • ericsson evolved packet gateway
CVE-2021-28485
In Ericsson Mobile Switching Center Server (MSC-S) before IS 3.1 CP22, the SIS web application allows relative path traversal via a specific parameter in the ht

In Ericsson Mobile Switching Center Server (MSC-S) before IS 3.1 CP22, the SIS web application allows relative path traversal via a specific parameter in the https request after authentication, which allows access to files on the system that are not intended to be accessible via the web application.

NVD description · AI analysis pending
4.3<1%
  • ericsson mobile switching center server bc 18a firmware
CVE-2022-46408
+1 in the same advisory: …46407
Ericsson Network Manager (ENM), versions prior to 22.1, contains a vulnerability in the application Network Connectivity Manager (NCM) where improper Neutraliza

Ericsson Network Manager (ENM), versions prior to 22.1, contains a vulnerability in the application Network Connectivity Manager (NCM) where improper Neutralization of Formula Elements in a CSV File can lead to remote code execution or data leakage via maliciously injected hyperlinks. The attacker would need admin/elevated access to exploit the vulnerability.

NVD description · AI analysis pending
6.8
group max
<1%
  • ericsson network manager
CVE-2021-32570
In Ericsson Network Manager (ENM) releases before 21.2, users belonging to the same AMOS authorization group can retrieve the data from certain log files.

In Ericsson Network Manager (ENM) releases before 21.2, users belonging to the same AMOS authorization group can retrieve the data from certain log files. All AMOS users are considered to be highly privileged users in ENM system and all must be previously defined and authorized by the Security Administrator. Those users can access some log’s files, under a common path, and read information stored in the log’s files in order to conduct privilege escalation.

NVD description · AI analysis pending
4.9<1%
  • ericsson network manager
CVE-2021-28488
Ericsson Network Manager (ENM) before 21.2 has incorrect access-control behavior (that only affects the level of access available to persons who were already gr

Ericsson Network Manager (ENM) before 21.2 has incorrect access-control behavior (that only affects the level of access available to persons who were already granted a highly privileged role). Users in the same AMOS authorization group can retrieve managed-network data that was not set to be accessible to the entire group (i.e., was only set to be accessible to a subset of that group).

NVD description · AI analysis pending
6.51%
  • ericsson network manager
CVE-2021-44217
In Ericsson CodeChecker through 6.18.0, a Stored Cross-site scripting (XSS) vulnerability in the comments component of the reports viewer allows remote attacker

In Ericsson CodeChecker through 6.18.0, a Stored Cross-site scripting (XSS) vulnerability in the comments component of the reports viewer allows remote attackers to inject arbitrary web script or HTML via the POST JSON data of the /CodeCheckerService API.

NVD description · AI analysis pending
6.12% PoC
  • ericsson codechecker
CVE-2021-43339
In Ericsson Network Location before 2021-07-31, it is possible for an authenticated attacker to inject commands via file_name in the export functionality.

In Ericsson Network Location before 2021-07-31, it is possible for an authenticated attacker to inject commands via file_name in the export functionality. For example, a new admin user could be created.

NVD description · AI analysis pending
8.810% PoC ×3
  • ericsson network location
CVE-2021-32569
+1 in the same advisory: …32571
In OSS-RC systems of the release 18B and older customer documentation browsing libraries under ALEX are subject to Cross-Site Scripting.

In OSS-RC systems of the release 18B and older customer documentation browsing libraries under ALEX are subject to Cross-Site Scripting. This problem is completely resolved in new Ericsson library browsing tool ELEX used in systems like Ericsson Network Manager. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. Ericsson Network Manager is a new generation OSS system which OSS-RC customers shall upgrade to

NVD description · AI analysis pending
6.1
group max
<1%
  • ericsson operations support system-radio and core firmware
CVE-2021-41390
+1 in the same advisory: …41391
In Ericsson ECM before 18.0, it was observed that Security Provider Endpoint in the User Profile Management Section is vulnerable to CSV Injection.

In Ericsson ECM before 18.0, it was observed that Security Provider Endpoint in the User Profile Management Section is vulnerable to CSV Injection.

NVD description · AI analysis pending
8.0
group max
1% PoC
  • ericsson enterprise content management
CVE-2020-29145
+1 in the same advisory: …29144
In Ericsson BSCS iX R18 Billing & Rating iX R18, ADMX is a web base module in BSCS iX that is vulnerable to stored XSS via the name or description field to a so

In Ericsson BSCS iX R18 Billing & Rating iX R18, ADMX is a web base module in BSCS iX that is vulnerable to stored XSS via the name or description field to a solutionUnitServlet?SuName=UserReferenceDataSU Access Rights Group. In most test cases, session hijacking was also possible by utilizing the XSS vulnerability. This potentially allows for full account takeover, or exploiting admins' browsers by using the beef framework.

NVD description · AI analysis pending
5.4<1% PoC
  • ericsson bscs ix r18 billing \& rating admx
  • ericsson bscs ix r18 billing \& rating mx
CVE-2020-7824
A vulnerability in the web-based management interface of iPECS could allow an authenticated, remote attacker to get administrator permission.

A vulnerability in the web-based management interface of iPECS could allow an authenticated, remote attacker to get administrator permission. The vulnerability is due to insecure permission when handling session cookies. An attacker could exploit this vulnerability by modification the cookie value to an affected device. A successful exploit could allow the attacker access to sensitive device information, which includes configuration files.

NVD description · AI analysis pending
6.51%
  • ericssonlg ipecs
CVE-2019-7417
XSS exists in Ericsson Active Library Explorer (ALEX) 14.3 in multiple parameters in the "/cgi-bin/alexserv" servlet, as demonstrated by the DB, FN, fn, or id p

XSS exists in Ericsson Active Library Explorer (ALEX) 14.3 in multiple parameters in the "/cgi-bin/alexserv" servlet, as demonstrated by the DB, FN, fn, or id parameter.

NVD description · AI analysis pending
6.12% PoC ×2
  • ericsson active library explorer
CVE-2018-15138
Ericsson-LG iPECS NMS 30M allows directory traversal via ipecs-cm/download?filename=../ URIs.

Ericsson-LG iPECS NMS 30M allows directory traversal via ipecs-cm/download?filename=../ URIs.

NVD description · AI analysis pending
7.513%
  • ericssonlg ipecs nms
CVE-2018-10285
+2 in the same advisory: …9245 …10286
The Ericsson-LG iPECS NMS A.1Ac web application uses incorrect access control mechanisms.

The Ericsson-LG iPECS NMS A.1Ac web application uses incorrect access control mechanisms. Since the app does not use any sort of session ID, an attacker might bypass authentication.

NVD description · AI analysis pending
9.8
group max
13%
  • ericssonlg ipecs nms